Taiwan Stock Exchange - Rules & Regulations Directory

Article NO. Content

Title:

Establishing Information Security Inspection Mechanisms for Securities Firms 

Amended Date: 2024.02.05 (Articles 1, 2 amended,English version coming soon)
Current English version amended on 2022.12.28 
Categories: Market Supervision > Regulation of Securities Firms
8
    Access Control (CC-18000, monthly audit)
  1. The company shall adopt rules governing controlled access of the information system and request the employees to abide by the rules in writing, electronically, or via other means.
  2. Authorization management:
    1. There shall be a detailed written description of the controls on the access to and use of programs.
    2. In the event of a personnel change, their use authorization shall be promptly updated.
    3. Access to and use of programs and files shall be granted on the basis of authorization.
    4. Authorization for computer access and use by outsourcers shall be subject to appropriate control, and the authorization shall be promptly reclaimed at the end of the outsourcing period.
    5. Outsourcers deployed to the company's premises shall be subject to the company's security management, and security control measures shall be applied if they wish to use internal network resources (e.g., where such personnel use a proxy server or establish a separate network, it is advisable that such sever or network be physically isolated from the internal network).
    6. Regular examination (at least semi-annually) and reconsideration shall be conducted with regard to the authorization of users who have not used the system for a long time (excluding users who are customers).
  3. Password Management:
    1. Users making use of the system for the first time may not operate the system until they have changed their initial password.
    2. Passwords should be generated and saved encrypted using publicly secure and uncracked algorithms (e.g., irreversible algorithms such as hashing algorithms).
    3. A user or customer who forgets his password shall go through a rigorous identity check of the company (such as verification of particulars with customer service, OTP, over-the-counter service etc.) before being allowed to use the system again.
    4. Initial passwords shall be generated randomly and have no connection with the user's or customer's identity. (This item is not applicable in the case of delivery of an electronic password slip by customized means.)
    5. The login session shall be terminated, the account blocked, and relevant records retained, when a password is inputted incorrectly three times. Upon receipt from a customer of an application for unlocking, the company shall verify the customer's identification (such as by verifying its particulars with customer service, OTP, over-the-counter service etc.) and retain relevant records before the company may entertain the application.
    6. Except for voice-mail ordering systems, the company shall use strong passwords (at least six characters in length with alphanumeric characters or other symbols) and exercise control, and further encourage customers to change their passwords at least once every three months. The company shall take proper measures if a customer's password has not been changed for over a year or the password changed is the same as the previous set. Except for customers, other users in the company must change their passwords at least once every three months. (To become effective as of 30 November 2022)
    7. The company's current website, servers, Network Neighborhood, routers, switches, operating systems, databases, and other software and hardware equipment shall be password-protected. Default settings (e.g. "administrator," "root," "sa") or simple strings (e.g. "1234") shall be avoided as passwords. The company shall not fail to set administrator access privileges.
    8. Where a customer applies for electronic trading, the company may deliver an electronic password slip by general or customized electronic means by following the description below:
      1. In the case of delivery of an electronic password slip by general electronic means, it shall send an OPT (One Time Password) to the mobile phone number left by the customer when the customer opens an account, and shall send an encrypted electronic password slip by electronic means to the electronic mailbox advised by the customer. With respect to such procedure, records of the relevant systems shall be retained.
      2. In the case of delivery of an electronic password slip by customized means, the operating procedure for determination of delivery of electronic transaction password and the security control method shall be established, and the identification of the person to whom the electronic transaction password is delivered shall be verified to be the intended person, and relevant records shall be retained.
  4. Management of computer audit logs:
    1. Audit logs for important systems (like server login systems and online order systems) shall include user ID numbers, login dates and times, computer identification information, and IP addresses etc.
    2. Specially appointed personnel shall be assigned to regularly inspect the computer audit logs of important systems above.
    3. With respect to the relevant records retained, there should be appropriate procedures to ensure collection and protection of digital evidence, and the records shall be kept for at least three years.
  5. Data Input Management:
    1. The inputting or alteration of high-security or important data may be undertaken only with approval from the supervisor with proper authority.
    2. A log shall be kept of the data that is input or altered along with the names and job titles of the people who perform the inputting or alteration.
    3. Important data (e.g. password files) that are highly confidential shall be saved in a randomized format.
    4. If the company is a public company, it shall incorporate the Guidelines for Online Filing of Public Information by Public Companies into its internal control system and carry out information reporting in accordance with those directions.
    5. Where an electronic certificate, IC card, other form of certificate chip card, or other certificate carrier is used to represent the company in transmitting signatures (e.g. the Market Observation Post System, the Securities Firm Filings Window, or Official-Document Exchange Center), specially appointed personnel shall be responsible for maintaining custody of the certificate carriers and establishing a log book. Procedures governing the use and custody of account numbers and passwords shall be adopted and implemented.
    6. When a certificate carrier is used to represent the company in transmitting signatures, if the server side is a security firm application system (e.g. Electronic Reconciliation Statement System), a computer audit log shall be kept for the same period as the data in each operation.
    7. The personal information of customers and the company's internal personnel shall be properly handled in accordance with the Personal Information Protection Act.
    8. The company shall at regular or irregular intervals audit the management of information defined as personal information by the Personal Information Protection Act.
    9. Any updates, edits, or strike-outs of the aforementioned personal information shall be reported for recordation, and a complete and accurate log shall be maintained showing the content of the updates, edits, strike-outs, the names of the persons making them and the times at which they were made.
    10. As the company needs to collect, process, and transmit internationally personal data for business purposes, the company shall adopt "The Partition of Rights and Liabilities with Regard to Maintenance of Secrecy and Damages with Software/Hardware Manufacturers."
  6. Management of Data Output:
    1. Whether statements are generated and delivered to the user units in a timely manner.
    2. Whether appropriate control procedures are in place for the printing out or browsing of confidential or sensitive statements.
    3. There shall be an encrypted transmission mechanism (e.g. SSL) for investors searching personal information on the company website.
    4. With regard to the transmission of reports on execution of electronic and non-electronic trades, the company shall handle the names, account numbers, credit account numbers and other confidential and sensitive information in accordance with the Principles of the Classification and Concealment of Confidential and Sensitive Information.

Interpretation:

Data Source:Taiwan Stock Exchange - Rules & Regulations Directory
twse-regulation.twse.com.tw